Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 18

Количество 18

fstec логотип

BDU:2022-00488

больше 4 лет назад

Уязвимость библиотеки Polkit и инструмента песочницы Bubblewrap, вызванная переполнением буфера на стеке, позволяющая нарушителю повысить свои привилегии до уровня суперпользователя

CVSS3: 7.8
EPSS: Критический
redos логотип

ROS-20220301-01

больше 4 лет назад

Уязвимость инструмента песочницы Bubblewrap

EPSS: Критический
redos логотип

ROS-20220128-01

больше 4 лет назад

Уязвимость библиотеки Polkit

EPSS: Критический
ubuntu логотип

CVE-2021-4034

больше 4 лет назад

A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool designed to allow unprivileged users to run commands as privileged users according predefined policies. The current version of pkexec doesn't handle the calling parameters count correctly and ends trying to execute environment variables as commands. An attacker can leverage this by crafting environment variables in such a way it'll induce pkexec to execute arbitrary code. When successfully executed the attack can cause a local privilege escalation given unprivileged users administrative rights on the target machine.

CVSS3: 7.8
EPSS: Критический
redhat логотип

CVE-2021-4034

больше 4 лет назад

A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool designed to allow unprivileged users to run commands as privileged users according predefined policies. The current version of pkexec doesn't handle the calling parameters count correctly and ends trying to execute environment variables as commands. An attacker can leverage this by crafting environment variables in such a way it'll induce pkexec to execute arbitrary code. When successfully executed the attack can cause a local privilege escalation given unprivileged users administrative rights on the target machine.

CVSS3: 7.8
EPSS: Критический
nvd логотип

CVE-2021-4034

больше 4 лет назад

A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool designed to allow unprivileged users to run commands as privileged users according predefined policies. The current version of pkexec doesn't handle the calling parameters count correctly and ends trying to execute environment variables as commands. An attacker can leverage this by crafting environment variables in such a way it'll induce pkexec to execute arbitrary code. When successfully executed the attack can cause a local privilege escalation given unprivileged users administrative rights on the target machine.

CVSS3: 7.8
EPSS: Критический
msrc логотип

CVE-2021-4034

больше 4 лет назад

A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool designed to allow unprivileged users to run commands as privileged users according predefined policies. The current version of pkexec doesn't handle the calling parameters count correctly and ends trying to execute environment variables as commands. An attacker can leverage this by crafting environment variables in such a way it'll induce pkexec to execute arbitrary code. When successfully executed the attack can cause a local privilege escalation given unprivileged users administrative rights on the target machine.

CVSS3: 7.8
EPSS: Критический
debian логотип

CVE-2021-4034

больше 4 лет назад

A local privilege escalation vulnerability was found on polkit's pkexe ...

CVSS3: 7.8
EPSS: Критический
suse-cvrf логотип

openSUSE-SU-2022:0190-1

больше 4 лет назад

Security update for polkit

EPSS: Критический
suse-cvrf логотип

SUSE-SU-2022:0191-1

больше 4 лет назад

Security update for polkit

EPSS: Критический
suse-cvrf логотип

SUSE-SU-2022:0190-1

больше 4 лет назад

Security update for polkit

EPSS: Критический
suse-cvrf логотип

SUSE-SU-2022:0189-1

больше 4 лет назад

Security update for polkit

EPSS: Критический
rocky логотип

RLSA-2022:267

больше 4 лет назад

Important: polkit security update

EPSS: Критический
rocky логотип

RLSA-2022:0267

больше 4 лет назад

Important: polkit security update

EPSS: Критический
github логотип

GHSA-qgr2-xgqv-24x8

больше 4 лет назад

A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool designed to allow unprivileged users to run commands as privileged users according predefined policies. The current version of pkexec doesn't handle the calling parameters count correctly and ends trying to execute environment variables as commands. An attacker can leverage this by crafting environment variables in such a way it'll induce pkexec to execute arbitrary code. When successfully executed the attack can cause a local privilege escalation given unprivileged users administrative rights on the target machine.

CVSS3: 7.8
EPSS: Критический
oracle-oval логотип

ELSA-2022-9073

больше 4 лет назад

ELSA-2022-9073: polkit security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2022-0274

больше 4 лет назад

ELSA-2022-0274: polkit security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2022-0267

больше 4 лет назад

ELSA-2022-0267: polkit security update (IMPORTANT)

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
fstec логотип
BDU:2022-00488

Уязвимость библиотеки Polkit и инструмента песочницы Bubblewrap, вызванная переполнением буфера на стеке, позволяющая нарушителю повысить свои привилегии до уровня суперпользователя

CVSS3: 7.8
95%
Критический
больше 4 лет назад
redos логотип
ROS-20220301-01

Уязвимость инструмента песочницы Bubblewrap

95%
Критический
больше 4 лет назад
redos логотип
ROS-20220128-01

Уязвимость библиотеки Polkit

95%
Критический
больше 4 лет назад
ubuntu логотип
CVE-2021-4034

A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool designed to allow unprivileged users to run commands as privileged users according predefined policies. The current version of pkexec doesn't handle the calling parameters count correctly and ends trying to execute environment variables as commands. An attacker can leverage this by crafting environment variables in such a way it'll induce pkexec to execute arbitrary code. When successfully executed the attack can cause a local privilege escalation given unprivileged users administrative rights on the target machine.

CVSS3: 7.8
95%
Критический
больше 4 лет назад
redhat логотип
CVE-2021-4034

A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool designed to allow unprivileged users to run commands as privileged users according predefined policies. The current version of pkexec doesn't handle the calling parameters count correctly and ends trying to execute environment variables as commands. An attacker can leverage this by crafting environment variables in such a way it'll induce pkexec to execute arbitrary code. When successfully executed the attack can cause a local privilege escalation given unprivileged users administrative rights on the target machine.

CVSS3: 7.8
95%
Критический
больше 4 лет назад
nvd логотип
CVE-2021-4034

A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool designed to allow unprivileged users to run commands as privileged users according predefined policies. The current version of pkexec doesn't handle the calling parameters count correctly and ends trying to execute environment variables as commands. An attacker can leverage this by crafting environment variables in such a way it'll induce pkexec to execute arbitrary code. When successfully executed the attack can cause a local privilege escalation given unprivileged users administrative rights on the target machine.

CVSS3: 7.8
95%
Критический
больше 4 лет назад
msrc логотип
CVE-2021-4034

A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool designed to allow unprivileged users to run commands as privileged users according predefined policies. The current version of pkexec doesn't handle the calling parameters count correctly and ends trying to execute environment variables as commands. An attacker can leverage this by crafting environment variables in such a way it'll induce pkexec to execute arbitrary code. When successfully executed the attack can cause a local privilege escalation given unprivileged users administrative rights on the target machine.

CVSS3: 7.8
95%
Критический
больше 4 лет назад
debian логотип
CVE-2021-4034

A local privilege escalation vulnerability was found on polkit's pkexe ...

CVSS3: 7.8
95%
Критический
больше 4 лет назад
suse-cvrf логотип
openSUSE-SU-2022:0190-1

Security update for polkit

95%
Критический
больше 4 лет назад
suse-cvrf логотип
SUSE-SU-2022:0191-1

Security update for polkit

95%
Критический
больше 4 лет назад
suse-cvrf логотип
SUSE-SU-2022:0190-1

Security update for polkit

95%
Критический
больше 4 лет назад
suse-cvrf логотип
SUSE-SU-2022:0189-1

Security update for polkit

95%
Критический
больше 4 лет назад
rocky логотип
RLSA-2022:267

Important: polkit security update

95%
Критический
больше 4 лет назад
rocky логотип
RLSA-2022:0267

Important: polkit security update

95%
Критический
больше 4 лет назад
github логотип
GHSA-qgr2-xgqv-24x8

A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool designed to allow unprivileged users to run commands as privileged users according predefined policies. The current version of pkexec doesn't handle the calling parameters count correctly and ends trying to execute environment variables as commands. An attacker can leverage this by crafting environment variables in such a way it'll induce pkexec to execute arbitrary code. When successfully executed the attack can cause a local privilege escalation given unprivileged users administrative rights on the target machine.

CVSS3: 7.8
95%
Критический
больше 4 лет назад
oracle-oval логотип
ELSA-2022-9073

ELSA-2022-9073: polkit security update (IMPORTANT)

больше 4 лет назад
oracle-oval логотип
ELSA-2022-0274

ELSA-2022-0274: polkit security update (IMPORTANT)

больше 4 лет назад
oracle-oval логотип
ELSA-2022-0267

ELSA-2022-0267: polkit security update (IMPORTANT)

больше 4 лет назад

Уязвимостей на страницу